3 ms·
Only once. I had an asterisk server with polycom phones on a network not connected to the internet and because I'm lazy all the phones had 1234 as their SIP pa
by olihb 17y ago
Only once.
I had an asterisk server with polycom phones on a network not connected to the internet and because I'm lazy all the phones had 1234 as their SIP password. If you're inside the building, you don't need to hack the server, just use the phone in front of you...
Fast forward a couple of years and now some of us work at home or telecommute. So I had to configure an asterisk server hosted in a datacenter. I used the same config files for the autoprovisionning of some of the phones.
Well, one of the account got exploited(SIP scanner that tried simple password on common extensions) and called thousands of numbers in Colorado(from Québec, so long distance) to fish for credit card numbers. Our termination provider saw that these calls didn't correspond to our normal usage pattern and deactivated our account until I called them.
In all, it only cost us 10$ in long distance fees because of the audit server of our provider(unlimitel.ca). Now all the phones and servers in our business have strong passwords. And I had no excuses, the phone are auto-provisioned so phone users don't even see their SIP password...